

SAP patch day is a critical board problem, not a quiet install
September’s SAP patch day has a maximum-severity kernel flaw, a second critical Message Server issue and a simple commercial lesson: patching is only the middle of the response.
By Katie Delaney / 2026-09-13 / 10 min read

Why this SAP patch day matters beyond the CVE list#
SAP’s 8 September security patch day released 19 new security notes and one update to a previously released note. CERT-EU then highlighted two critical vulnerabilities in a 9 September advisory. CVE-2026-44756 carries a CVSS score of 10.0 and affects Extended Passport processing in the SAP Kernel. CVE-2026-58240 carries 9.8 and affects the SAP NetWeaver Message Server. The CERT-EU advisory and SAP’s patch-day page are the controlling sources for the headline facts.
The score is a prioritisation signal, not a complete incident assessment. Both flaws are described as remotely exploitable without authentication. The advisory says successful exploitation could lead to operating-system command execution under the account that owns the SAP installation, with consequences for the confidentiality, integrity and availability of the affected system. The strongest compromise wording is attributed to Onapsis research in the advisory, so a careful SAP vulnerability response keeps the distinction visible between a confirmed defect and a researcher’s impact assessment.
The business reason to move quickly on this SAP patch day is not drama. SAP sits inside finance, procurement, manufacturing, payroll and logistics processes. A technical compromise can become a reconciliation problem, an availability problem or a trust problem with customers and suppliers. That is why the first briefing should name a technical owner, a business owner and a communications owner. It should also say what is not yet known. Risk reading, response routing and recovery rehearsal make the story useful to a board without pretending the advisory has already proved an intrusion.
Do not let a familiar monthly window make the SAP patch day decision for you. The advisory recommends applying SAP Security Notes 3747649 and 3759472 as soon as possible. The CVE record for CVE-2026-44756 and the CVE record for CVE-2026-58240 give the identifiers a stable reference point. The response can be urgent and still be precise.
Two flaws, two exposure paths#
The first issue is a memory corruption vulnerability in SAP Extended Passport processing. CERT-EU says SAP addressed it with Security Note 3747649. The affected product list spans several Kernel families and Web Dispatcher versions, so a response that searches only for one application name can miss an exposed component. The Onapsis OVERPASS remediation note can provide additional technical context, but the customer’s exact patch level should come from SAP’s support material.
The second issue is a missing authentication check in the SAP NetWeaver Message Server, addressed with Security Note 3759472. CERT-EU describes the component as insufficiently validating the authenticity of internal application-server components during registration. Onapsis says the attack path can promote an attacker to a trusted node inside a cluster. That is a different operational question from the Kernel flaw. The team needs to know which systems expose Message Server network access, which versions run, and which controls would detect an unexpected registration.
This is where SAP Kernel security becomes a system inventory exercise. A good inventory records the product, version, host, network path, owner, business service, backup status, maintenance window and evidence location. It also records the negative result when a search finds no match. An empty cell is not proof of safety, but an unexplained cell is a prompt to investigate. Asset accuracy, access awareness and patch precision are more valuable than a colourful severity badge.
Be equally careful with language about exploitation. CERT-EU says both flaws are remotely exploitable without authentication and recommends immediate updates. The advisory does not establish that every SAP environment is exposed or that every affected environment has been attacked. It also cites researcher assessments for full compromise. The Onapsis patch-day analysis and S4GET advisory should be read as research context, not as a substitute for local evidence.
| Item | Value |
|---|---|
| new SAP security notes | 19 |
| updated note | 1 |
| critical CVEs highlighted by CERT-EU | 2 |
critical notes to own first

A useful response starts before reassurance#
Start with identification. Search the estate for the affected Kernel and Message Server versions, then trace each result to a service owner. Do not rely on a single CMDB export if SAP instances are managed by several partners. Confirm the installed patch level through the approved support route and capture the evidence. The SAP security notes index is the appropriate starting point for the vendor’s remediation instructions.
Next, define the exposure question. Is the relevant port reachable from the internet, from a partner network or only from a segmented internal zone? Does the Message Server accept registrations from places it should not? Has the environment changed since the last review? For a public-facing asset, containment and monitoring may need to run while the patch is prepared. For an internal asset, the same urgency can still apply if lateral movement would reach an important business process. Perimeter proof matters because an untested assumption is not a control.
Then patch with a rollback and recovery plan. “Apply the note” is not a complete change record. Record the pre-change version, the note applied, the person who approved it, the test performed, the application owner’s acceptance and the point at which the service would be restored or rolled back. Test the business transaction, not only the process health check. A green service does not prove that invoices, interfaces and scheduled jobs still behave correctly.
Finally, look for signs that deserve escalation. Unexpected administrative accounts, changed authorisations, unrecognised components, unusual process execution, new outbound connections or unexplained data access should enter the incident route. Do not turn a hunt into a claim of compromise without evidence. The FIRST CVSS material explains what the score is designed to represent, while the SAP security overview provides wider vendor context.
Find affected Kernel, Web Dispatcher and Message Server versions, owners and network paths.
Check reachability, trust boundaries, registration behaviour and recent changes.
Follow SAP Security Notes 3747649 and 3759472 through an approved change.
Run technical and business transaction checks, with rollback evidence recorded.
Escalate indicators through incident response without overstating what the evidence proves.
The Message Server needs a named business owner#
Security work often stalls where the component has no obvious commercial owner. A Message Server can sound like infrastructure, while the consequences belong to finance, manufacturing or customer operations. Name both sides. The technical team owns the configuration and patch evidence. The service owner decides the acceptable maintenance window and confirms the business test. The risk owner decides what happens if the window moves. This is the difference between a ticket and owned exposure.
For communications, lead with what is known, what is being checked and when the next update will be available. Avoid a theatrical claim that every SAP customer is compromised. Avoid the opposite comfort that no public exploitation report means no action is needed. The current evidence supports urgent remediation and verification. It does not support a universal statement about local compromise. Plain language, proof points and calm cadence protect trust better than a dramatic banner.
Partners should receive a precise request. Ask for the affected product list, patch plan, exposure evidence, logging coverage and post-change test result. Ask who can authorise emergency work. Ask where evidence will be stored. If a partner says an environment is “not vulnerable”, request the version and configuration basis. A claim without a check is difficult to defend in an audit and impossible to use in a later incident review.
Malta and wider European organisations may also need to align the technical response with their wider resilience and reporting duties. This article is operational guidance, not legal advice. The ENISA NIS2 material and CERT-EU advisory index can help locate the relevant European context, but applicability depends on the organisation and jurisdiction.

What good looks like after the patch#
A successful SAP vulnerability response ends with evidence that someone else can understand. The record names the affected asset, the original version, the note applied, the date, the approver, the test, the result and the remaining uncertainty. It links to the source advisory and the internal change. It states whether the environment had internet exposure and whether detection found anything unusual. This is audit-ready action, not administrative polish.
The next rehearsal should be scheduled before the urgency fades. Ask how quickly the organisation can identify a vulnerable instance, reach the owner, restrict exposure, apply the note and test a critical transaction. Capture the time and the friction. If the answer depends on a single person or a supplier mailbox, that dependency is part of the risk. Fast finding, focused fixing and future-proofing are the real lessons of a patch cycle.
For a cybersecurity provider, this is also a communications opportunity with a hard edge. Sell the service around inventory confidence, exposure evidence, change control and recovery proof. Do not sell panic. A cybersecurity marketing programme should help a buyer explain the problem internally, not simply repeat the CVSS number. A content marketing programme can carry the same discipline into the customer’s own education and response materials.
The headline is simple: SAP patch day is a starting gun. The organisation earns confidence by showing what it checked, what it changed and what it can prove. The forest is quiet only after the lantern has reached the corners.
For the response record, name the SAP patch day, the SAP vulnerability response owner, the SAP Kernel security check, the SAP NetWeaver Message Server exposure and the CVE-2026-44756 evidence. Then let the fox’s scent, trail and track guide the review through the brush and thicket and back to the den. That is not decoration. It is a reminder that evidence has to travel from technical detail to accountable action. The SAP patch day record should also show who owns verification.
Keep one short post-change note for the next team. State what was patched, what was tested, what was not tested and who owns the remaining work. A future responder should not have to reconstruct the incident from chat fragments or memory. The note is the small lantern that makes the next forest easier to cross. A second SAP patch day should begin with that record, not with a new guess about the estate.
Keep the SAP patch day brief operational. A clear SAP vulnerability response should identify the SAP Kernel security path, the SAP NetWeaver Message Server exposure path and the owner of the CVE-2026-44756 check. That gives the den a trail to follow, a patch to verify and a recovery question to answer.
CVE-2026-44756 is a maximum-severity (CVSS 10.0) memory corruption bug in the Extended Passport (EPP) processing component of the SAP kernel.
A patch is a change. Confidence is the evidence around it.
Frequently asked questions#
What happened on SAP patch day in September 2026?
SAP released 19 new security notes and one update on 8 September 2026. CERT-EU highlighted two critical vulnerabilities, including a CVSS 10.0 SAP Kernel issue and a CVSS 9.8 SAP NetWeaver Message Server issue.
What is CVE-2026-44756?
It is a memory corruption vulnerability in SAP Extended Passport processing. CERT-EU says it is remotely exploitable without authentication and recommends applying SAP Security Note 3747649 as soon as possible.
What is SAP vulnerability response?
It is the owned process of confirming affected assets, checking exposure, applying vendor remediation, testing business services, hunting for indicators and recording what the evidence proves.
What is SAP Kernel security?
SAP Kernel security covers the shared runtime components and related controls that support SAP applications. The exact versions and affected products must be checked against the current SAP security notes and local estate.
Why does the SAP NetWeaver Message Server matter?
The Message Server helps coordinate application-server components. The September advisory describes a missing authentication check that could let an unauthenticated attacker register unauthorised components, so network exposure and registration behaviour need review.
Does a critical CVSS score prove a breach?
No. CVSS helps describe vulnerability severity. It does not prove that a specific environment is exposed, exploited or suffering business impact. Those claims require local technical and incident evidence.
Read more on this topic#
Microsoft security update triage
Why a patch cycle needs prioritisation, ownership and verification around the update itself.
Read the field noteCybersecurityPasskey phishing and cloud identity protection
A look at the boundary between a security control and the way teams explain its limits.
Read the field noteCybersecurityCyber resilience reporting
How incident readiness becomes a practical operating responsibility.
Read the field noteNeed a response plan that survives the incident room?
folkfox helps cybersecurity teams turn urgent technical evidence into clear, accountable communications and buyer-facing content.
Want folkfox in your Google results and AI answers? Set folkfox as a preferred source.